Welcome to Gravity Help
Appendix

Security

gravity operates on the microsoft power platform, which is centrally managed within the microsoft 365 tenant in order to access gravity, users must first be established within the microsoft tenant and adhere to the existing security profiles security measures such as multi factor authentication (mfa), strong passwords, single sign on (sso), and security groups are all managed at the microsoft level after a user has been established at the microsoft tenant level, they will be assigned one or more security roles in gravity these security roles determine the user's permissions for creating, reading, writing, and deleting records furthermore, they can also manage row level security, allowing the user to perform tasks either on their own records or on the entire organization's records microsoft security roles are extended in gravity to include the ability to execute processes like printing documents, posting transactions and printing reports this is maintained under the miscellaneous security privileges in system settings finally gravity provides security on the entities a user has access to and the processes they can perform note when custom security roles are created, they must be extended with a miscellaneous security privilege record see miscellaneous security privlidges docid\ som4i1gl5xhpfwusthpqs security security roles security roles are accessed from the https //admin powerplatform microsoft com/ https //admin powerplatform microsoft com/ portal under environment settings each security role can be examined by selecting it and can be copied into a new role gravity provides the following standard security roles power user can perform all of gravity's functions including system settings financial user can only access financial records and financial reports journal entries bank book entries bank reconciliation budgeting ar user can access all revenue functions and revenue reports order entry picking shipping invoice entry cash receipts deposit tickets customers ap user can access all expense functions and expense reports purchase order receiving ap automation voucher entry quick bill/check select checks check maintenance apply to maintenance vendors ap user limited similar to the ap user but cannot process payments read only user read only access to all functions and reports administrator access to system setup options only dashboards access to gravity's predefined dashboards note it is recommended to avoid modifying the predefined gravity security roles and instead create new roles during an upgrade, the default security roles will be overwritten and any modifications will be lost for a detailed list of each security role download the attached file https //archbee doc uploads s3 amazonaws com/x2aa mkmiqid52voc g4k/5u 8rkd1yuqix9r5ne3z gravity security roles xlsx entity access user entity access can either be defined on the user security account or on the entity record under entity configuration on the user account in the platform settings, select the user and add the entities under the financial entity access on the entity, select user access and add users to the entity miscellaneous security privileges gravity extends the security roles with additional privileges see miscellaneous security privlidges docid\ som4i1gl5xhpfwusthpqs